PT-2025-46779 · WordPress · Sureforms

Published

2025-11-13

·

Updated

2026-04-07

·

CVE-2025-12536

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SureForms plugin for WordPress versions prior to 1.14.0
Description The SureForms plugin for WordPress is susceptible to sensitive information disclosure in versions up to and including 1.13.1. This is a result of the auth callback parameter being set to return true during the registration of the ' srfm email notification' post meta, which permits unauthenticated access to the metadata. Successful exploitation allows unauthenticated attackers to extract sensitive data, including email notification configurations. These configurations often contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that could be exploited to inject malicious data into downstream systems.
Recommendations Update the SureForms plugin to version 1.14.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12536

Affected Products

Sureforms